nerdexam
Microsoft

SC-200 · Question #180

You plan to review Microsoft Defender for Cloud alerts by using a third-party security information and event management (SIEM) solution. You need to locate alerts that indicate the use of the…

The correct answer is B. Intent. In the JSON representation of Microsoft Defender for Cloud alerts, the 'Intent' field maps directly to MITRE ATT&CK tactics (e.g., Reconnaissance, Lateral Movement, Privilege Escalation, Exfiltration). To find alerts associated with the Privilege Escalation tactic, you search…

Submitted by parkjh· Apr 18, 2026Manage threat mitigation using Microsoft Defender for Cloud

Question

You plan to review Microsoft Defender for Cloud alerts by using a third-party security information and event management (SIEM) solution. You need to locate alerts that indicate the use of the Privilege Escalation MITRE ATT&CK tactic. Which JSON key should you search?

Options

  • ADescription
  • BIntent
  • CExtendedProperies
  • DEntities

How the community answered

(17 responses)
  • B
    94% (16)
  • D
    6% (1)

Explanation

In the JSON representation of Microsoft Defender for Cloud alerts, the 'Intent' field maps directly to MITRE ATT&CK tactics (e.g., Reconnaissance, Lateral Movement, Privilege Escalation, Exfiltration). To find alerts associated with the Privilege Escalation tactic, you search the 'Intent' key for that value. 'Description' contains human-readable text, 'ExtendedProperties' holds additional metadata, and 'Entities' lists affected resources - none of these directly encode the MITRE tactic.

Topics

#Defender for Cloud#SIEM integration#Alert data model#MITRE ATT&CK

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice